---
id: CVE-2026-60956
title: >-
  Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD
  Edwards (component: Payroll)
summary: >-
  Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD
  Edwards (component: Payroll).   The supported version that is affected is 9.2.
  Difficult to exploit vulnerability allows low privileged attacker with network
  a…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
published: '2026-08-18'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-60956'
references:
  - url: 'https://www.oracle.com/security-alerts/cspuaug2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
epss: 0.00334
epssPercentile: 0.24063
ingestedAt: '2026-08-22T14:33:16.608Z'
---

## Overview

Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD Edwards (component: Payroll).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne US Payroll.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne US Payroll. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
